Economic firewall for agents

An economic firewall
for AI agents.

Keep your agents within budget. Make external agents pay before they use your API. Get a signed receipt for every decision.

SatGate checks each request before it reaches your API or MCP tool. Your own agents stop when their budget runs out. External agents pay on the routes you choose, so hammering your API gets expensive, and paying never gets them past your access rules.

Build with SatGate·See a signed receipt (Evidence Pack)

14 days free. No credit card.

REST · GraphQL · MCP Gateway · Sidecar · MCP Proxy Checks each request first
MCP · HTTP APIs · Lightning payments Open source
live recording · cloud.satgate.io
3¢ budget · call 4 refused

Recorded on production: three $0.01 tool calls, then the fourth is refused before the tool runs.

See how it works

See SatGate in Action

Two short recordings from production, with narration.

Your agents: a budget they can't overspend

Mint an agent token with a 3¢ budget, watch each MCP tool call get a signed receipt, see call four refused before the tool runs, then check the receipt with the open-source verifier.

The agent in the recording is a scripted MCP client using the public satgate-mcp-bridge npm package. Tokens are blurred.

External agents: pay before they get in

Set a price on a route in the dashboard. An agent with no wallet gets 402 Payment Required and never reaches your API. You choose how external agents pay on each paid route: Lightning, USDC on Base, or both. With USDC, each payment buys one request. On Lightning routes you choose how many requests one payment buys. In the recording, an agent pays a 10-sat invoice and gets through. On sat-priced routes the price can rise under load, up to a ceiling you set, and unpaid 402s do not raise it. Paying never gets an agent past your access rules, and payment decisions, refusals included, get a signed receipt.

The agents in the recording are scripted HTTP clients. The invoice was paid from a separate Lightning wallet while the recording was paused. Emails are blurred.

Check the refusal from the start of the video yourself. Fetch the live receipt or the downloaded copy, then run the open-source verifier against SatGate's public key:

python3 tools/verify_evidence_pack.py https://api.satgate.io/v1/evidence/evid_GrXvKUgtdqNbuQ5lZzqRMpZrOoU2VAnE --jwks-url https://api.satgate.io/.well-known/jwks.json --require-trusted-issuer

What the verifier checks

Budgets for your agents. Payment from external agents.

Control caps what your own agents can spend. Admit makes external agents pay before their request reaches you. Both leave signed receipts.

ON BY DEFAULT

Agents only get what you allow

Every route except the ones you mark PUBLIC

Before SatGate forwards a request, it checks what that agent is allowed to do. Paying doesn't change that: a paid request still can't go past its permissions, use an expired token or get around a revoke.

✓ Permissions per agent✓ Narrower tokens for sub-agents✓ Revoke works on the next request✓ Signed receipts

Your agents: budgets

Protected by default →

Observe (see usage)

See usage and cost without blocking requests.

Start here. Nothing is blocked while you see which agents call what, and what it costs.

  • ✓ Nothing is blocked; your agents work as before
  • ✓ Usage broken down by team and cost center
  • ✓ See which agents, tools and routes cost the most before you change anything
  • ✓ Built to add little overhead
Protected by default →

Control (budgets)

Enforce budgets and permissions before a request runs.

Then turn on limits. An agent that is out of budget or asks for something it isn't allowed is stopped before the request runs.

  • ✓ Budget checked on every request
  • ✓ Your agents spend from a budget you set; nobody pays per call
  • ✓ Per-agent spending caps

External agents: access and payment

Protected by default →

Admit (external access)

Give external agents limited access, and charge them where you want to.

On a paid route, payment comes first, before the request reaches your API, so hammering it gets expensive. Paying never gets an agent past your access rules.

  • ✓ No shared API keys to hand out
  • ✓ Payment only on the routes you choose
  • ✓ You set the price and how many requests one payment buys
  • ✓ You decide what each agent can reach
RECEIPTS FOR BOTH

Receipts anyone can check

From Observe, Control and Admit

When SatGate allows, refuses, charges or revokes, it signs a receipt. Receipts roll up into an Evidence Pack. Your auditor can check the signatures with the open-source verifier, without having to trust us. A receipt shows what SatGate decided. It is not a compliance certificate.

✓ Your agents and external agents✓ Refusals too✓ Any edit breaks the signature✓ Open-source verifier

Charging for access makes abuse more expensive. It doesn't replace rate limits or access controls, and it only covers traffic that goes through SatGate.

Why API keys don't work when agents hand off work

An API key gives full access or none. A SatGate token carries its own budget, permissions and expiry. An agent can hand a sub-agent a narrower token, never a broader one.

Mark a route PUBLIC to leave it open, for health checks (/healthz), docs and webhooks. Every other route is protected by default.

🚗💨 HOW IT WORKS

Badge in once. Fly through every gate.

An agent gets a token when it starts, like putting an E-ZPass on the windshield. After that, SatGate checks and meters each request as it passes.

Agent StartsK8s / AWS / OIDC
→
MintBadge in (once)
→
EZ PassCapability token
→
Toll GateVerify · Meter · Budget
→
UpstreamYour API

SatGate checks the token itself, so it doesn't call your identity provider on every request.

THE RESEARCH

Built for agents that hand work to other agents

A 2026 paper on AI delegation describes a problem we see in practice: when agents hand work to other agents, each one needs clear limits on what it can do and spend. One approach it proposes is tokens that can only be narrowed as they are passed down, such as macaroons.

SatGate's tokens are macaroons.

Limited permissions

Each agent gets only the permissions it needs, and each handoff can only narrow them.

Budget caps

Set budgets per agent and per route. SatGate checks them before forwarding.

Stops on the next request

Once an agent hits a limit, SatGate refuses its next request.

We built SatGate because standing API keys and after-the-fact alerts are a bad fit for autonomous systems. The paper put words to a problem we were already seeing in agent deployments. - Tomasev et al., 2026

Where it fits

Three ways to set it up. Start with one route or one tool.

STANDARD

CDN / WAF
↓
SatGate
↓
Your API

REST, GraphQL, any HTTP endpoint

SIDECAR

Existing Gateway
↓
Legacy traffic
↓
SatGate
↓
↓
Your APIs

Route only agent traffic through SatGate

MCP PROXY

AI Agents
↓
SatGate MCP Proxy
↓
MCP Servers / Tools

Budgets per tool, including for sub-agents

How it works

Most teams start by pointing one endpoint or one MCP tool at SatGate.

1

Pick a policy

Set a policy per route: public for health checks and docs, protected for everything else.

routes:
  - path: /healthz
    policy: public
  - path: /v1/*
    policy: observe
  - path: /premium/*
    policy: charge
2

Apply it

Apply it when you are ready. Every version is kept, with a receipt for who changed what, so you can roll back.

v3 (applied) ← current
v2 (available)
v1 (available)

Receipt: who, when, diff
3

Point your agents

Send agent traffic to api.satgate.io with your tenant header, so every request goes through SatGate.

# Agent requests
GET https://api.satgate.io/v1/...
X-SatGate-Tenant: your-tenant

# MCP clients
npx satgate-mcp-bridge
4

Check what happened

Receipts for allowed, denied, paid, delegated, and revoked decisions, ready to export as an Evidence Pack.

Illustrative sample, not live customer data
Allowed receipts: 1,203
Denied receipts: 12,847
Paid receipts:   $847 settled
Delegations:     42
Revocations:     9

→ Export Evidence Pack

FAQ

Questions

What is SatGate?

SatGate is a gateway that sits in front of your APIs and MCP tools. It keeps your own agents within the budgets and permissions you set, charges external agents on the routes you choose, and signs a receipt for each decision.

How does SatGate control what agents do?

Before a request reaches your API or MCP tool, SatGate checks the agent’s permissions, its remaining budget and whether its token was revoked. If a check fails, the request stops at SatGate.

How do I give an agent a budget?

You set the budget, the permissions and how many times it can hand work to a sub-agent. The agent gets a token with those limits built in. Every allow, refusal, payment, handoff and revoke gets a receipt.